3 ms·
Maybe I'm paranoid, but I advice to my customers that any passphrase with an entropy below 80 bits is insecure, around 140 bit is fairly secure, and anything ab
by JohnStrange 9y ago
Maybe I'm paranoid, but I advice to my customers that any passphrase with an entropy below 80 bits is insecure, around 140 bit is fairly secure, and anything above 200 bit entropy is very secure.
- Abekkus 9y agoAssuming that password complexity is the weak link in their practices.
- JohnStrange 9y agoUhm, no, independently of that...
- contravariant 9y agoI can understand why you'd want to be more careful with generated passphrases, but 80 bits of entropy is like a 16 character long alphanumeric password. That seems fairly secure to me for most purposes. Unless the hash is 'broken' but then your options are fairly limited anyway.
- JohnStrange 9y ago80 bits of entropy is between 12 and 13 visible ASCII characters and between 14-15 ASCII letters. Yes, if you go below that I'd say it's insecure. It's a conservative estimate, I admit. An entropy of 60 might be okay, too, but there is no harm in making passwords more secure.
- Bromskloss 9y ago> but there is no harm in making passwords more secure. Well, it makes them harder to remember and slower to type (and increases the chance of making an error and having to type it again). I hesitate slightly to do things that require me to type my long password. :-)